First published: Mon Dec 09 2024(Updated: )
Dell ECS, versions prior to 3.8.0, contain(s) a Host Header Injection Vulnerability. A remote low-privileged attacker could potentially exploit this vulnerability to trigger redirections that leads to sensitive information leakage.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell EMC Elastic Cloud Storage | <3.8.0 | |
Dell EMC Elastic Cloud Storage | <3.8.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-38485 is considered a low-severity vulnerability that allows potential exploitations leading to sensitive information leakage.
To mitigate CVE-2024-38485, upgrade Dell ECS to version 3.8.0 or later.
The impact of CVE-2024-38485 includes the potential for sensitive information leakage through redirection triggered by a remote attacker.
CVE-2024-38485 affects users of Dell ECS versions prior to 3.8.0.
Yes, CVE-2024-38485 can be exploited by a remote low-privileged attacker.